ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
Summary
| CVE | CVE-2026-9494 |
|---|---|
| State | PUBLISHED |
| Assigner | canonical |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-16 13:16:34 UTC |
| Updated | 2026-07-16 16:19:16 UTC |
| Description | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.001030000 probability, percentile 0.011550000 (date 2026-07-20)
Problem Types: CWE-214 | CWE-214 CWE-214 Invocation of process using visible sensitive information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 5.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Canonical | Ubuntu-pro-client Ubuntu-advantage-tools | affected 37.3 python | Linux |
| CNA | Canonical | Ubuntu 26.04 LTS | unaffected 37.2ubuntu0.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 24.04 LTS | unaffected 37.2ubuntu~24.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 22.04 LTS | unaffected 37.2ubuntu~22.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 20.04 LTS | unaffected 37.1ubuntu0~20.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 18.04 LTS | unaffected 37.1ubuntu0~18.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 16.04 LTS | unaffected 37.1ubuntu0~16.04.1 dpkg | Linux |
| CNA | Canonical | Ubuntu 14.04 LTS | unaffected 19.7ubuntu0.1 dpkg | Linux |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ubuntu.com/security/CVE-2026-9494 | [email protected] | ubuntu.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Bilal Teke (en)
There are currently no legacy QID mappings associated with this CVE.